The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Inspect TPM readinessGet-Tpm | Select-Object TpmPresent, TpmReady, TpmEnabled, TpmActivated, RestartPending, LockedOutView examples
Audit BitLocker volumesGet-BitLockerVolume | Select-Object MountPoint, VolumeType, VolumeStatus, ProtectionStatus, EncryptionMethod, EncryptionPercentageView examples
Check status with manage-bdemanage-bde.exe -status C:View examples
List protector metadata(Get-BitLockerVolume -MountPoint $env:SystemDrive).KeyProtector | Select-Object KeyProtectorId, KeyProtectorTypeView examples
Resolve recovery protector ID(Get-BitLockerVolume $env:SystemDrive).KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword' | Select-Object KeyProtectorIdView examples
Back up to Microsoft Entra IDBackupToAAD-BitLockerKeyProtector -MountPoint ` $env:SystemDrive -KeyProtectorId ` '{RECOVERY-PROTECTOR-GUID}'View examples
Back up to AD DSBackup-BitLockerKeyProtector -MountPoint ` $env:SystemDrive -KeyProtectorId ` '{RECOVERY-PROTECTOR-GUID}'View examples
Preview TPM enablementEnable-BitLocker -MountPoint $env:SystemDrive ` -EncryptionMethod XtsAes256 -TpmProtector ` -UsedSpaceOnly -WhatIfView examples
Preview adding recoveryAdd-BitLockerKeyProtector -MountPoint $env:SystemDrive ` -RecoveryPasswordProtector -WhatIfView examples
Preview one-reboot suspensionSuspend-BitLocker -MountPoint $env:SystemDrive ` -RebootCount 1 -WhatIfView examples
Preview protection resumeResume-BitLocker -MountPoint $env:SystemDrive -WhatIfView examples
Verify protection resumedGet-BitLockerVolume $env:SystemDrive | Select-Object MountPoint, VolumeStatus, ProtectionStatus, LockStatusView examples
Audit automatic unlockGet-BitLockerVolume | Select-Object MountPoint, VolumeType, AutoUnlockEnabled, ProtectionStatusView examples
Preview disabling auto-unlockDisable-BitLockerAutoUnlock -MountPoint 'D:' -WhatIfView examples
Preview BitLocker decryptionDisable-BitLocker -MountPoint 'D:' -WhatIfView examples
Read BitLocker eventsGet-WinEvent -LogName ` 'Microsoft-Windows-BitLocker/BitLocker Management' ` -MaxEvents 50View examples

BitLocker encrypts volumes; a key protector controls how the volume encryption key is released, and a TPM can bind release to measured boot state. Encryption percentage alone does not prove that protection is active. Inventory volume status, protection status, TPM readiness, and protector types together. Before enabling, suspending, rotating, decrypting, or changing firmware, verify recovery information is securely escrowed away from the protected device and that authorized staff can retrieve it.

Step by step

Detailed examples

01

Establish TPM, volume, and protection state separately

Get-Tpm describes the local TPM, while Get-BitLockerVolume describes encryption and protectors. TpmPresent is not the same as TpmReady. Likewise, a FullyEncrypted volume can have ProtectionStatus Off if its protectors are suspended. Run read-only inventory first, from an elevated Windows PowerShell session when access is restricted, and record edition, join state, policy source, firmware plans, and restart requirements.

Read-only BitLocker and TPM baseline
Get-Tpm | Select-Object TpmPresent, TpmReady, TpmEnabled, TpmActivated, RestartPending, LockedOut
Get-BitLockerVolume | Select-Object MountPoint, VolumeType, VolumeStatus, ProtectionStatus, EncryptionMethod, EncryptionPercentage, LockStatus
manage-bde.exe -status $env:SystemDrive
Back to quick reference ↑
02

Treat key protectors as access policy, not encryption algorithms

A volume encryption key can have multiple protectors, such as TPM, TPM plus PIN, recovery password, startup key, or certificate. Protector choice defines unlock and recovery paths; it does not change the volume's encryption method. Inventory IDs and types without printing RecoveryPassword. A recovery password grants access to all data on the volume, so never paste it into tickets, logs, shell history, screenshots, or shared transcripts.

Privacy-preserving protector inventory
$volume = Get-BitLockerVolume -MountPoint $env:SystemDrive
$volume | Select-Object MountPoint, EncryptionMethod, VolumeStatus, ProtectionStatus
$volume.KeyProtector | Select-Object KeyProtectorId, KeyProtectorType
Back to quick reference ↑
03

Prove recovery escrow before depending on a protector

Use the recovery-password protector GUID shown at recovery to locate the matching secret in the organization's approved vault. Microsoft recommends Microsoft Entra ID for Entra-joined devices and AD DS for domain-joined devices. Backup cmdlets require elevation, the appropriate join and permissions, and successful directory connectivity. Their success proves submission, not that the help desk can retrieve the key under incident conditions; test that process without exposing the password.

Resolve the escrow target without revealing the password
$recovery = (Get-BitLockerVolume $env:SystemDrive).KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword'
$recovery | Select-Object KeyProtectorId, KeyProtectorType
# After approval, pass the exact KeyProtectorId to BackupToAAD-BitLockerKeyProtector or Backup-BitLockerKeyProtector.
# Verify authorized recovery in the directory portal; do not print or log RecoveryPassword.
Back to quick reference ↑
04

Design policy and recovery before starting encryption

Enable-BitLocker can begin a long-running storage change and may require elevation, policy compliance, compatible hardware, free space, and a hardware test. UsedSpaceOnly is faster for new devices but is not a substitute for sanitizing previously used free space. Choose the encryption method through managed policy before deployment because changing it later requires full decryption and re-encryption. A TPM-only protector improves unattended startup but recovery must exist independently. Preview supported cmdlets with WhatIf and deploy through managed policy at scale.

Review an enablement proposal without changing the volume
$proposal = [pscustomobject]@{ MountPoint = $env:SystemDrive; Method = 'XtsAes256'; Protector = 'TPM'; Scope = 'Used space only' }
$proposal | Format-List
Enable-BitLocker -MountPoint $env:SystemDrive -EncryptionMethod XtsAes256 -TpmProtector -UsedSpaceOnly -WhatIf
Add-BitLockerKeyProtector -MountPoint $env:SystemDrive -RecoveryPasswordProtector -WhatIf
Back to quick reference ↑
05

Bound every suspension and verify the resume

Firmware and boot-component maintenance can trigger recovery when TPM measurements change. Suspension keeps data encrypted but makes the volume key available in the clear and disables normal boot-integrity validation, so it is a temporary security reduction. Use the smallest approved RebootCount, preserve recovery access, keep the device physically controlled, and verify ProtectionStatus after the final restart. A value of zero is indefinite and should be avoided unless an explicit resume is tightly controlled.

Preview and verify a one-restart maintenance window
Get-BitLockerVolume $env:SystemDrive | Select-Object MountPoint, VolumeStatus, ProtectionStatus
Suspend-BitLocker -MountPoint $env:SystemDrive -RebootCount 1 -WhatIf
# Perform the approved change only after recovery escrow is verified.
Resume-BitLocker -MountPoint $env:SystemDrive -WhatIf
# After maintenance, rerun Get-BitLockerVolume and require ProtectionStatus On.
Back to quick reference ↑
06

Audit automatic unlock as an inherited trust decision

Automatic unlock stores information protected by the operating-system volume so an encrypted data volume opens after Windows unlocks. It improves availability but links the data volume's access to the OS volume and user context. Inventory each volume and confirm the behavior matches device ownership, removable-media policy, separation requirements, and recovery design. Changes normally require elevation; use WhatIf where supported.

Review data-volume automatic unlock
Get-BitLockerVolume | Where-Object VolumeType -ne 'OperatingSystem' | Select-Object MountPoint, VolumeType, VolumeStatus, ProtectionStatus, AutoUnlockEnabled
Disable-BitLockerAutoUnlock -MountPoint 'D:' -WhatIf
Back to quick reference ↑
07

Distinguish suspension, locking, and full decryption

Suspension leaves sectors encrypted but weakens how the key is protected. Locking denies access to an encrypted data volume until an authorized unlock. Disable-BitLocker starts decrypting and ultimately removes BitLocker protection and protectors; it can take substantial time and increases exposure of data at rest. Confirm legal retention, device transfer, backup, power, maintenance, and monitoring requirements before approval, and never mistake pause or resume of conversion for protection suspend or resume.

Review a proposed decryption without executing it
$volume = Get-BitLockerVolume -MountPoint 'D:'
$volume | Select-Object MountPoint, VolumeStatus, ProtectionStatus, EncryptionPercentage, LockStatus
Disable-BitLocker -MountPoint 'D:' -WhatIf
# Decryption is disruptive and removes at-rest protection; execute only through an approved change.
Back to quick reference ↑
08

Collect evidence before changing TPM or protectors

Unexpected recovery can follow firmware, Secure Boot, boot configuration, hardware, docking, or policy changes. Capture the recovery-key ID displayed to the user, timestamps, BitLocker events, TPM state, recent changes, and protector metadata without collecting the recovery password. Do not clear the TPM as a generic fix: clearing resets it and can make TPM-protected credentials and keys unavailable. Identify the root cause, regain authorized access, and rotate a recovery password after use according to policy.

Nonsecret recovery evidence bundle
Get-Tpm | Select-Object TpmPresent, TpmReady, RestartPending, LockedOut
Get-BitLockerVolume $env:SystemDrive | Select-Object MountPoint, VolumeStatus, ProtectionStatus, EncryptionMethod
(Get-BitLockerVolume $env:SystemDrive).KeyProtector | Select-Object KeyProtectorId, KeyProtectorType
Get-WinEvent -LogName 'Microsoft-Windows-BitLocker/BitLocker Management' -MaxEvents 50
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftBitLocker overviewlearn.microsoft.com
  2. MicrosoftBitLocker operations guidelearn.microsoft.com
  3. MicrosoftBitLocker recovery overviewlearn.microsoft.com
  4. MicrosoftBitLocker PowerShell modulelearn.microsoft.com
  5. MicrosoftTrusted Platform Module technology overviewlearn.microsoft.com
  6. MicrosoftGet-Tpmlearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback